Doc #80843 [Com]: Remove examples from comments as they are invariably insecure

From: Date: Fri, 30 Dec 2022 05:50:50 +0000
Subject: Doc #80843 [Com]: Remove examples from comments as they are invariably insecure
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-19538@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80843&edit=1

 ID:                 80843
 Comment by:         amin dot jab242 at gmail dot com
 Reported by:        maarten dot bodewes at gmail dot com
 Summary:            Remove examples from comments as they are invariably
                     insecure
 Status:             Open
 Type:               Documentation Problem
 Package:            OpenSSL related
 PHP Version:        8.0.3
 Block user comment: N
 Private report:     N

 New Comment:

Thanks (https://www.dinarrecaps.org/)github.com


Previous Comments:
------------------------------------------------------------------------
[2021-03-07 11:38:06] maarten dot bodewes at gmail dot com

Description:
------------
---
From manual page: https://php.net/function.openssl-encrypt
---

Remove examples from the comments sections of the OpenSSL libraries as they are invariably insecure.

Here the most upvoted example for some reason uses SHA3 for HMAC, which is unnecessarily strong and
very slow compared to e.g. SHA-256. Much worse is that the IV is not included in the HMAC
calculation, which means an attacker can change each of the initial 16 bytes at will. The problem is
that I can leave a comment, but it will take years before it gets noticed.

Please remove all those examples from security functions because COPY/PASTE security doesn't
exist. At least not from unknown sources that for some reason get upvoted and can never be
retracted. Comments should only be applicable to the function itself.

Please write the sample code yourself and have it reviewed by a security professional because the
authors of the OpenSSL library clearly are not very capable either; if you confuse passwords and
keys then you've got some things to learn yet.

I'm Maarten Bodewes. I've corrected (terrible) examples of mcrypt_encrypt before and
indicated that mcrypt was insecure and unmaintained. I'm #1 user for the cryptography tags at
StackOverflow and mod at the cryptography site of StackExchange.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80843&edit=1


Thread (2 messages)

« previous php.doc.bugs (#19538) next »